Open menu

Personal Data Protection Law

20March2020

Coronavirus (COVID-19) Pandemic and Its Relation with KVKK

Due to the Covid-19 virus, necessary precautions have been taken by the organizations; within the scope of these precautions, the possibility of unauthorized access to personal data has emerged, including health data of employees or third parties. Organizations should be very careful to avoid possible violations which might directly impact the rights and freedoms of persons when taking relevant preventive measures. In this process, organizations can follow the methods in the precautions to be taken, which are elaborated as follows:

1. Remote Working

In order to ensure business continuity, an organization may go for the option of remote working in this period. In such case, if organizations do not already have sufficient technical infrastructure, certain difficulties may be faced. For example, within the scope of this measure taken to protect public health, the personal phone numbers of people who do not use the company phone for communication between people, other employees, business partners, customers, suppliers etc., can be shared with third parties. While this transfer/sharing of information has a legitimate aim, it is well known that it must be based on the explicit consent of individuals. In cases where people do not give explicit consent or withdraw their explicit consent, providing a company line to the person would be an appropriate solution.

Author CottGroup Hukuk ve Mevzuat Ekibi, Category Personal Data Protection Law

10January2020

Online Complaint Module Has Been Put Into Service for Data Subjects

Pursuant to the following provision of the Article 15 of the Law "The Board shall carry out the necessary examination on the matters falling within its task upon complaint or ex officio where it has learnt about the alleged infringement.", complaints reported to the Authority are reviewed by the Board.

Complaints were used to be reported to the Authority via paper mail; as per the announcement of the Board dated 09.01.2020, the complaints can now be reported electronically via online module.

The data subject will be able to report complaint in person via complaint module by logging into the e-government system and the complaints to be reported through the attorney will continue as it is.

Author CottGroup Hukuk ve Mevzuat Ekibi, Category Personal Data Protection Law

08January2020

Change of Application in Notification of Personal Data Breach to the Board

As it is known, in accordance with the Board Decision dated 24.01.2019 and numbered 2019/10, in case of a personal data breach, a notification should be made to the Authority by using Data Breach Notification Form as per the Board Decision.

According to the announcement made by the Authority on 06.01.2020, Personal Data Breach Notification that previously expected to be sent by paper mail can now be made on the internet at ihlalbildirim.kvkk.gov.tr.

Author CottGroup Hukuk ve Mevzuat Ekibi, Category Personal Data Protection Law

27December2019

VERBIS Registry Deadlines Has Been Postponed

The publication below may be out of date due to postponements and recent announcements. Please contact your client representative to have further information and for your queries about the recent announcements regarding your legal obligations.

According to the decision of the Personal Data Protection Authority (“KVKK”) dated 17.12.2019 numbered 2019/387, the deadline for registration obligation to Data Controllers' Registry Information System ("VERBIS") has been extended.

Author CottGroup Hukuk ve Mevzuat Ekibi, CottGroup Hukuk ve Mevzuat Ekibi, Category Personal Data Protection Law

<<  6 7 8 9 10 11 12 13 14 15  >>